Apple Hide My Email flaw: a recent discovery has revealed that Apple’s iCloud+ feature, Hide My Email, can still leak your real email address even after two attempted fixes. This vulnerability undermines the feature’s promise of privacy, as researchers found that in certain cases, the forwarding mechanism may embed your original address in email headers or reply-to fields. This allows third parties to extract your identity, defeating the purpose of using a random alias.
The flaw manifests when email servers use advanced authentication protocols like DKIM or SPF. These protocols can cause Apple’s relay to fail in fully anonymizing the message. Testing across 50 email services showed that roughly 10% leaked real addresses through this Apple Hide My Email flaw, shocking users and privacy experts alike.
Apple released two patches to address the issue, but both fell short. The company acknowledged the flaw internally, calling it minor, but experts argue that even isolated leaks are unacceptable for a feature marketed as a privacy cornerstone. The persistent Apple Hide My Email flaw suggests a deeper architectural problem in Apple’s centralized relay system.
To protect yourself, avoid using Hide My Email for sensitive accounts like banking. Use it only for low-stakes sign-ups. Regularly inspect raw email headers for leaks and consider alternative privacy tools like DuckDuckGo’s Email Protection. Stay updated on future fixes.
In conclusion, the Apple Hide My Email flaw is a stark reminder that no privacy tool is perfect. While Apple works on a permanent solution, users must stay vigilant and take proactive steps to protect their digital identities.
